Bugzilla versions below 2.20 are susceptible to multiple information leaks.
57cd438a2820f029676c4439a217c2b29e6b506f7b887a2dd556c7fb869285db
Bugzilla versions prior to 2.18.2 are susceptible to multiple information leak vulnerabilities.
1508db168c61c8f0b39f934929e4aeb10bf23f34aa5611dc6f2552a578166bb2
This advisory covers three security bugs that have recently been discovered and fixed in the Bugzilla code: In the stable 2.16 releases, it is possible to make a specific change to a bug without permissions; and in the 2.18 release candidate, there are information leaks with private attachments and comments.
8f9c02f007a21f436c69cf3d72153a7a8d2ed21ef3cb018145a3e685a21f230a